Skip to content

Latest commit

 

History

History
24 lines (14 loc) · 1.07 KB

File metadata and controls

24 lines (14 loc) · 1.07 KB

Security Policy

opub CLI handles local provider credentials and starts funded local agent sessions. Please keep reports minimal and sanitized.

Please Do Not Include

Do not include provider keys, OAuth tokens, .env files, prompts, responses, private code, raw provider payloads, or other secrets in GitHub issues, discussions, logs, screenshots, or reproduction archives.

Sensitive Areas

Security-sensitive areas include:

  • Credential storage and fallback --insecure-storage behavior.
  • Secretless MCP boundaries and local session state.
  • Agent environment injection for Copilot CLI, Claude Code, and Codex.
  • Installer behavior, release artifacts, and checksum verification.

MCP must remain secretless. It must not be expanded to artifact tracking, prompt tracking, response tracking, private-code tracking, or work-unit tracking.

Reporting

For private reports, email hello@opub.dev with a short summary and a sanitized reproduction path. Please do not attach secrets or raw provider payloads.

Public issues are welcome for non-sensitive bugs and documentation problems.